Trust

Security and privacy, built in.

Dinify is designed to protect your restaurant's and your guests' data at every layer.

What you get

Trust highlights

Payments secured by Stripe — PCI DSS Level 1

Card numbers never touch Dinify's servers. We store only the card brand and last 4 digits for display.

Encrypted in transit — TLS 1.2+ with HSTS

Traffic between you and Dinify is encrypted, with HSTS to keep it that way.

Privacy by design

Aligned with PIPEDA, GDPR, CCPA and Québec Law 25.

CASL-compliant marketing

Express and implied consent, with one-click unsubscribe on every message.

Tenant isolation & role-based access

Each restaurant's data is walled off, with least-privilege roles per team member.

Audit logging

Sensitive actions are recorded so there's a trail of who did what.

Under the hood

How we protect your data

Encryption in transit

All traffic runs over TLS 1.2 or higher, with HSTS to prevent downgrade.

Hardened accounts

Passwords are hashed with bcrypt, sessions use short-lived JWTs, and repeated failed logins trigger brute-force lockout.

Rate limiting

Sensitive endpoints are rate-limited to blunt abuse and automated attacks.

Input validation

Requests are validated and sanitised, with protection against NoSQL injection.

Least-privilege access

Role-based access control means staff only see and do what their role allows.

Tenant isolation

Each restaurant's data is isolated per tenant, so one restaurant can't reach another's.

Append-only audit logs

Authentication and money-affecting actions are written to append-only audit logs.

Payments

Diners pay into the restaurant's own Stripe account. Dinify never holds card data — card numbers never touch our servers. Stripe is certified PCI DSS Level 1, the highest level of payment-card security.

Your privacy rights

Guests can access, export or delete their data — self-service in the Dinify diner app, or by emailing info@dinify.ca. Restaurants can request their data per our Data Processing Agreement. See our Privacy Policy.

Who processes data

Subprocessors

The trusted providers we use to run Dinify, and what each does.

SubprocessorPurpose
StripePayments
TwilioSMS / OTP
Amazon Web ServicesHosting, storage and email
CloudflareCDN and DNS
Fly.ioApp hosting
MongoDB AtlasDatabase
Google FirebasePhone verification
Google MapsLocation
AnthropicAI features — processes menu text and diner chat
SendGridEmail

Legacy providers no longer used for new processing: Razorpay, Clover. See our Data Processing Agreement for details and contractual safeguards (SCCs).

Compliance roadmap

We align our controls to SOC 2 and ISO/IEC 27001 principles. A SOC 2 Type II examination is on our roadmap; we will publish the report here once complete.

Run your restaurant on a platform built to protect it.

Start free — no credit card, no hardware, no lock-in. Or book a demo and we'll walk you through how your data is kept safe.